CVE-2025-25732

Incorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows attackers to replace password hashes stored in the EEPROM with hashes of their own, leading to the escalation of privileges to root.
Configurations

No configuration.

History

29 Aug 2025, 16:22

Type Values Removed Values Added
Summary
  • (es) Un control de acceso incorrecto en el componente EEPROM de Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, y v4.6.0.1211.28 permite a los atacantes reemplazar los hashes de contraseñas almacenados en la EEPROM con sus propios hashes, lo que lleva a la escalada de privilegios a root.

26 Aug 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-284

26 Aug 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-26 15:15

Updated : 2025-08-29 16:22


NVD link : CVE-2025-25732

Mitre link : CVE-2025-25732

CVE.ORG link : CVE-2025-25732


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control